Skip to content

SCADA / ICS

Industrial control systems (ICS) and SCADA operate physical infrastructure: energy, water, manufacturing, transport. Their security inverts IT’s priorities —here availability and physical safety come first— and a failure can have real-world consequences, not just data ones.

PLC Programmable Logic Controller: runs the control logic of the physical process
RTU Remote Terminal Unit: telemetry/control in a remote field
HMI Human-Machine Interface: the operator's panel
SCADA supervision and data acquisition (central)
DCS Distributed Control System (plants)
Historian time-series database of the process
Level 5/4 corporate IT / ERP
Level 3.5 industrial DMZ (IT/OT separation zone) <- key control point
Level 3 plant operations (historian, engineering)
Level 2 supervision (SCADA/HMI)
Level 1 control (PLC/RTU)
Level 0 physical process (sensors/actuators)
# IT/OT segmentation at the industrial DMZ is the main structural defense
IT C-I-A: Confidentiality first
OT A-I-C (+ SAFETY): Availability and physical safety first
# you can't "reboot to patch" a turbine; maintenance windows are rare
# equipment decades old, protocols without authentication, can't be touched lightly
Threats access from IT (pivot), social engineering, USB, vendor remote access,
PLC logic tampering, ransomware jumping to OT
Defense Purdue segmentation + industrial DMZ, data diodes (unidirectional),
PASSIVE monitoring (don't actively scan a fragile PLC), allowlisting,
controlled remote access (jump host + MFA), vendor management
MITRE ATT&CK for ICS TTPs specific to industrial environments
OT monitoring Nozomi, Claroty, Dragos (passive, by protocol)
Standards IEC 62443 (the OT standard), NIST SP 800-82, NERC CIP (energy)
# NEVER scan/exploit a production ICS without a lab or an authorized window
  • Segmenting IT/OT (Purdue + industrial DMZ) is the #1 structural defense; no flat network.
  • Passive per-protocol monitoring (Nozomi/Claroty/Dragos): an active scan can take a PLC down.
  • Controlled vendor remote access (jump host + MFA + recording); manage the supply chain.
  • Align with IEC 62443/NIST 800-82; prioritize safety and availability over confidentiality.
  • Stuxnet (2010): manipulated Siemens PLCs to damage Iranian centrifuges; reached an air-gapped network via USB.
  • Industroyer/CrashOverride (2016) and Industroyer2 (2022): malware designed for power outages in Ukraine.
  • TRITON/TRISIS (2017): attacked a plant’s safety systems (SIS), risking lives.
  • OT asset inventory (PLC/RTU/HMI/SCADA) and Purdue architecture
  • IT/OT segmentation verified (industrial DMZ, no flat network)
  • Passive per-protocol monitoring deployed
  • Controlled vendor remote access (jump host + MFA)
  • Tests ONLY in a lab/authorized window (never active scanning in prod)
  • Map to MITRE ATT&CK for ICS
  • IEC 62443 / NIST 800-82 / NERC CIP compliance per sector